Maël Valais

Maël Valais

Senior Software Engineer, CyberArk

Toulouse, France

Actions

Maël Valais is a Software Engineer at Venafi. Maël has been working in the cloud-native space for the past 5 years and has been a maintainer on the cert-manager project for the past 2 years. Before becoming a software engineer, Maël used to be in academia and defended his PhD in symbolic logic in 2018.

Area of Expertise

  • Information & Communications Technology

Topics

  • Kubernetes
  • PKI infrastructure
  • cert-manager
  • Networking

Kubectl Controllers: Bridging DevOps Tooling Gaps Without Developing

Unleash the potential of ‘kubectl --watch’, ‘jq’, and ‘bash’ as you hack your own Kubernetes controllers directly from your terminal, addressing the DevOps solution gaps without relying on kopf, Go, or controller-runtime. Through hands-on demos, you will learn how ‘kubectl’, probably already at your disposal, can be harnessed to automate tasks such as transforming Secrets without init containers, synchronizing resources to another cluster, or pre-provisioning ExternalSecrets.

After attending this talk, you will feel comfortable with the concepts of reconciliation loop, desired state and observed state. Not only will you be able to discern the differences between operators and controllers, but you will also comprehend the trade-offs and alternatives to devising your own bespoke Bash controller. Prepare for a dive into the core Kubernetes’ controller model!

kpt vs. Helm: Demystifying Declarative Application Management on Kubernetes

Installing cert-manager and its addons can be a challenging task. Currently, we often rely on Helm for installation, but users experience difficulties with dependency management, complexity, and CRDs. At Venafi, we researched how tools like Helm, kpt, and flux work and demystified some of their magic, allowing us to better understand technical user problems and help users make informed decisions.

You will learn:
- the technical challenges of declarative application management on Kubernetes
(“resource dependency ordering“, “resource pruning“, “status checking“, “configuration drift“, “versioning“)
- the different solutions for these challenges
(Server Side Apply vs. 3-way merging, labelling vs. inventory objects, …)
- when to utilise Operators, GitOps, or CLI Tools for application deployment.

Project Maintainers Explain cert-manager in 5 Levels of Difficulty

Discover the depths of cert-manager as project maintainers unveil its intricacies across five levels of difficulty.
Gain insights into available features, use cases, and best practices.
From beginners to experts, this talk equips you to conquer cert-manager with confidence.

Level 1: Obtain TLS certificates from pre-configured issuers using Ingress/ Gateway annotations.
Level 2: Configure ACME Issuers and generate Secrets with private key + certificate chain using Certificate resources.
Level 3: Issue certificates from private PKIs and distribute CAs with trust-manager.
Level 4: Start using CSI-drivers and approver-policy plugins.
Level 5: Develop custom issuers, CSI-drivers, or approver-policy plugins.

Dive Into cert-manager and Start Contributing!

Join us for a hands-on, interactive session with the cert-manager maintainers and community! cert-manager, a graduated CNCF project, automates certificate management for Kubernetes and is a critical component for securing cloud-native applications. This workshop is perfect for both first-time contributors and seasoned open-source enthusiasts. You'll learn about cert-manager's architecture, the role of its key components, and how to set up your environment to start contributing. We’ll walk through the contribution process, tackle curated GitHub issues, and provide guidance tailored to your skill level. Whether you're interested in improving code, documentation, or community engagement, this session offers a great way to make an impact while learning valuable skills. Let’s build cert-manager together!

Cryptographically Signed Swag: cert-manager’s Stamped Certificates

It’s the hottest KubeCon swag on the block: printed, wax-stamped X.509 certificates to take home and show off.

Since we started issuing these little certs in KubeCon Valencia back in May 2022, the cert-manager project pavilion booth has been a smash-hit success - in Chicago last year we issued so many certs that we ran out of wax!

But there’s more to the story than just the swag; these certs are issued on a local Kubernetes cluster running cert-manager, and the story of how we went from a concept to a certificate in your hand is interesting and illustrative for cert-manager as a project, generally!

In this talk we'll discuss:

- How we got to this point: a brief history of cert-manager.
- The technical stuff: how does the KubeCon certificate printer work?
- What's new: exciting changes since last year!
- What we can learn: how the same technology is used to secure critical infrastructure around the world!

Maël Valais

Senior Software Engineer, CyberArk

Toulouse, France

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top